英国AI顾问Grant de Swardt在2024年8月4日发现其Claude Max账户出现异常1。在完全未进行任何工作的情况下,其账户代币使用量从45%无故增至55%1。经Anthropic确认,de Swardt的会话密钥遭到破坏,第三方获得了未授权访问权限1。
Anthropic表示,黑客使用常见的信息窃取恶意软件从用户电脑窃取Claude登录会话1。该公司通过Reddit和GitHub发现多名用户遭遇类似情况,包括账户被自动升级和代币瞬间耗尽的现象1。Anthropic对de Swardt的账户进行了暂停并提供部分退款£44.49,同时无效化了所有会话和OAuth代币1。
Anthropic账户支持系统存在缺陷,仅能追踪总使用量而无法提供具体使用明细,即便用户明确请求也无法获得1。此外,Anthropic拒绝向用户提供识别滥用行为的相关信息1。在账户恢复两周后,de Swardt已取消了其Claude订阅并转向使用Cursor1。
Claude subscription users have become targets of token theft through information-stealing malware. 1 Grant de Swardt, a UK-based AI advisor, discovered the breach when his Claude Max account began consuming tokens despite remaining inactive, with usage climbing from 45% to 55% without any corresponding work activity. 1 Anthropic subsequently confirmed that de Swardt's session key had been compromised and accessed by unauthorized third parties. 1
The company identified the attack vector as common information-stealing malware, with hackers extracting Claude login sessions directly from users' computers. 1 Following de Swardt's initial discovery on August 4, 2024, similar incidents were reported by multiple users across Reddit and GitHub, some experiencing automatic account upgrades and rapid token depletion. 1 Anthropic's response included suspending affected accounts, issuing partial refunds—de Swardt received £44.49—and invalidating all active sessions and OAuth tokens. 1
However, users faced significant obstacles in detecting and documenting the abuse. 1 Anthropic's account support system can only track total token usage rather than providing detailed breakdowns by project or activity, leaving customers unable to pinpoint which queries consumed their credits even when requesting detailed logs. 1 The company also declined to offer guidance on how users could identify unauthorized activity on their accounts. 1 De Swardt's account was eventually restored after two weeks, but he subsequently cancelled his subscription in favor of alternative services like Cursor. 1
评论
还没有评论,欢迎留下第一条。